R0106-HP MSR Router Series Security Command Reference(V7)
84
• If the source IP address of the packet is the IP address of a managed NAS, the server processes the
packet.
• If the source IP address of the packet is not the IP address of a managed NAS, the server drops the
packet.
When you use both the nas-ip command and hwtacacs nas-ip command, the following guidelines
apply:
• The setting configured by using the nas-ip command in HWTACACS scheme view is effective only
for the HWTACACS scheme.
• The setting configured by using the hwtacacs nas-ip command in system view is effective for all
HWTACACS schemes.
• The setting in HWTACACS scheme view takes precedence over the setting in system view.
If you execute the command multiple times, the most recent configuration takes effect.
Examples
# Set the source address for outgoing HWTACACS packets to 10.1.1.1 for HWTACACS scheme hwt1.
<Sysname> system-view
[Sysname] hwtacacs scheme hwt1
[Sysname-hwtacacs-hwt1] nas-ip 10.1.1.1
Related commands
hwtacacs nas-ip
primary accounting (HWTACACS scheme view)
Use primary accounting to specify the primary HWTACACS accounting server.
Use undo primary accounting to remove the configuration.
Syntax
primary accounting { ipv4-address | ipv6 ipv6-address } [ port-number | key { cipher | simple } string
| single-connection | vpn-instance vpn-instance-name ] *
undo primary accounting
Default
No primary HWTACACS accounting server is specified.
Views
HWTACACS scheme view
Predefined user roles
network-admin
Parameters
ipv4-address: Specifies an IPv4 address of the primary HWTACACS accounting server.
ipv6 ipv6-address: Specifies an IPv6 address of the primary HWTACACS accounting server.
port-number: Specifies the service port number of the primary HWTACACS accounting server. The value
range for the TCP port number is 1 to 65535, and the default setting is 49.
key { cipher | simple } string: Sets the shared key for secure communication with the primary
HWTACACS accounting server.